Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Single Sign On in High Availibility

Posted on 2013-01-27
6
Medium Priority
?
787 Views
Last Modified: 2013-02-20
Hello Friends,

I am trying to setup SSO service in HA mode.
I did install SSO on 2 nodes SSO-A and SSO-B.
I am using a virtual appliance load balancer.

On load balancer, configured a virtual server with name as SSOHA.domain.com and assigned 2 IP addresses to it.
This virtual server has the 2 nodes added to it as a pool of servers..

I am trying to install Inventory service and when it asks for SSO server, I am providing it with virtual server FQDN i.e., https://ssoha.domain.com:7444/lookupservice/sdk
but this is not going through..

What confuse me is the SSL.
As each SSO server by default has a self signed SSL, and I rem from my previous single node (basic) installation of SSO that the Inventory service installation prompted me to accept the SSL cert of SSO server after providing the installation with the URL https://SSOsrv.domain.com:7444/lookupservice/sdk.

Now when I have these nodes behind the load balancer, the Inventory service is not able to make connection. (this is what think).

There are possibilities that I am going totally wrong.

Does SSO support hardware LB?
I tried to find something on google, not specific.
If it does support, what should be the generic configuration of LB..
do i have to import the SSL in LB?

cannot find vmware KB, except the one that shows config of a software LB.

I might have confused some of you guys, plz do ask to understand the scenario and help to find solution.

Thanks.
0
Comment
Question by:Vaseem Mohammed
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 12

Author Comment

by:Vaseem Mohammed
ID: 38824042
I have gone through this page and up-gradate docs.
There is no specifics for configuring a HLB.
Can you tell me to which section in your posted article should I refer?
0
 
LVL 10

Expert Comment

by:millardjk
ID: 38826563
The thumbprint for the SSL cert will get saved by the inventory service; it can't be varying from time-to-time. That means you'll need to either export the cert from one of the two SSO hosts and import it on the other, or use a 3rd-party cert and import it into both appliances.

Second, your load balancer shouldn't have 2 IPs associated with the SSO FQDN; it should have ony 1. The nodes of the LB will each have a "private" IP, used for management, but the object they're balancing will have an independent IP.

Finally, support for LB and HA on SSO is a delicate piece with VMware. Essentially, they say it can be done, but if you have problems with it, they'll require you to show that the problem exists without the LB before they'll help fix something. It's classic 1.0 software support, and the community has been giving VMware negative feedback on this topic since SSO was released.

In summary, SSO is a Web service. If standard practices are observed for creating the HA environment of a web server, then it is believed that it should work.
0
Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

 
LVL 12

Author Comment

by:Vaseem Mohammed
ID: 38827097
Thanks for your input..

I found an article on vmware KB which is exactly what has to be done to setup SSO HA.
It does not explain why to do and in which scenario, but gives a good info over it.
I am trying to work on it.

The key points in article is forwarding the service URLs which are in-bound request to Virtual Server on NLB to nodes in back-end. i.e., SSO-A and SSO-B.

Stingray Traffic manager is a bit tricky to configure.. and trying to figure out how to get it done.

As far as SSL part, you are correct when it comes to installing a single SSO node (basic install)

In HA scenario, SSO-A is installed  and configured, SSO-B will take SSL thumbprint from SSO-A. then inventory service will.

There are many more confusions coming in, for what am trying to sort 1 by 1.

I would like to keep this question open if someone can give some more valuable inputs.
0
 
LVL 12

Accepted Solution

by:
Vaseem Mohammed earned 0 total points
ID: 38880206
Hello Friends,

Finally managed to figure out how to get vCenter 5.1 SSO working in HA scenario.
I have uploaded a step-by-step procedure at http://vhomelab.com/?p=880 and http://msxchange.wordpress.com/2013/02/12/vcenter-5-1-installation-and-vcenter-single-sign-in-high-availability-using-load-balancer

Do comment in case you have some questions or if any step in article is incorrect according to your knowledge.
0
 
LVL 12

Author Closing Comment

by:Vaseem Mohammed
ID: 38908744
The configuration on LB has to be precised to make other vCenter 5.1 roles communication with SSO nodes behind load balancer.
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this step by step tutorial with screenshots, we will show you HOW TO: Enable SSH Remote Access on a VMware vSphere Hypervisor 6.5 (ESXi 6.5). This is important if you need to enable SSH remote access for additional troubleshooting of the ESXi hos…
This article outlines why you need to choose a backup solution that protects your entire environment – including your VMware ESXi and Microsoft Hyper-V virtualization hosts – not just your virtual machines.
Teach the user how to install ESXi 5.5 and configure the management network System Requirements: ESXi Installation:  Management Network Configuration: Management Network Testing:
Teach the user how to use configure the vCenter Server storage filters Open vSphere Web Client:  Navigate to vCenter Server Advanced Settings: Add the four vCenter Server storage filters: Review the advanced settings: Modify the values of the four v…

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question